Martyn Simpson
Chief Information Security Officer
SaaS Security, Governance, Risk & Trust
I help SaaS leaders turn security, resilience and customer trust into practical business decisions, supporting enterprise growth, effective governance and transaction readiness.
My work spans board-level risk, customer assurance, governance, resilience and the decisions where commercial ambition meets responsible risk management.
Board and investor engagement
SaaS security leadership
Customer and commercial assurance
Governance and risk
Resilience and incident leadership
Transaction readiness
How I help
Security and risk governance
Helping leadership teams identify material security risk, make proportionate decisions and establish clear accountability.
SaaS trust and enterprise readiness
Building assurance and customer-trust approaches that support enterprise growth without creating unnecessary bureaucracy.
Resilience and critical decisions
Providing calm direction around incidents, vulnerabilities, business continuity, data governance and difficult technology-risk trade-offs.
Selected impact
Security programme
Built and matured the security programme for a growing B2B SaaS provider.
Board confidence
Led board and investor engagement across security, resilience, incidents and strategic risk.
Customer trust
Established a public Trust Center and customer-facing whitepaper series.
Commercial support
Supported material new and recurring revenue through enterprise assurance.
Compliance programmes
Led and supported programmes across ISO 27001, Cyber Essentials, Cyber Essentials Plus, ISO 9001, HIPAA and SOC 2 Type II.
Transaction readiness
Supported acquisition due diligence and engagement with prospective purchasers.
Selected work
Preservica Trust Center
A public assurance programme making security, privacy, compliance and resilience evidence more accessible to customers.
CISO Assurance whitepaper series
Practical whitepapers covering AI security, privacy, customer trust, data residency and access governance.
Speaking and commentary
Public discussion covering digital preservation, Microsoft 365, AI governance and long-term information risk.
Selective advisory
I am open to a small number of light-touch advisory relationships with SaaS and technology businesses that need pragmatic security, resilience or customer-trust guidance.
Latest Insight
- Securing Vibe-Coded Apps: Control the Boundary, Not Every Line of CodeAI-assisted development is making it possible for people across a business to create useful internal applications without traditional software-development teams. For security leaders, the challenge is deciding which risks need to be controlled centrally — without attempting to turn every small internal tool into a fully governed enterprise application. “Vibe coding” creates an interesting problem… Read more: Securing Vibe-Coded Apps: Control the Boundary, Not Every Line of Code
- The Difference Between Being Secure and Being TrustedSecurity and trust are related, but they are not the same. For SaaS businesses, credible assurance connects real operating controls to clear, useful evidence.
